$cfg['logs_debug_level']) return; $file = $cfg['logs_path'].'ranksystem.log'; if ($loglevel == 1) { $loglevel = " CRITICAL "; } elseif ($loglevel == 2) { $loglevel = " ERROR "; } elseif ($loglevel == 3) { $loglevel = " WARNING "; } elseif ($loglevel == 4) { $loglevel = " NOTICE "; } elseif ($loglevel == 5) { $loglevel = " INFO "; } elseif ($loglevel == 6) { $loglevel = " DEBUG "; } $loghandle = fopen($file, 'a'); fwrite($loghandle, DateTime::createFromFormat('U.u', number_format(microtime(true), 6, '.', ''))->setTimeZone(new DateTimeZone($cfg['logs_timezone']))->format("Y-m-d H:i:s.u ").$loglevel.$logtext."\n"); fclose($loghandle); if($norotate == false && filesize($file) > ($cfg['logs_rotation_size'] * 1048576)) { $loghandle = fopen($file, 'a'); fwrite($loghandle, DateTime::createFromFormat('U.u', number_format(microtime(true), 6, '.', ''))->setTimeZone(new DateTimeZone($cfg['logs_timezone']))->format("Y-m-d H:i:s.u ")." NOTICE Logfile filesie of 5 MiB reached.. Rotate logfile.\n"); fclose($loghandle); $file2 = "$file.old"; if(file_exists($file2)) unlink($file2); rename($file, $file2); $loghandle = fopen($file, 'a'); fwrite($loghandle, DateTime::createFromFormat('U.u', number_format(microtime(true), 6, '.', ''))->setTimeZone(new DateTimeZone($cfg['logs_timezone']))->format("Y-m-d H:i:s.u ")." NOTICE Rotated logfile...\n"); fclose($loghandle); } } function getclientip() { if (!empty($_SERVER['HTTP_CLIENT_IP'])) return $_SERVER['HTTP_CLIENT_IP']; elseif(!empty($_SERVER['HTTP_X_FORWARDED_FOR'])) return $_SERVER['HTTP_X_FORWARDED_FOR']; elseif(!empty($_SERVER['HTTP_X_FORWARDED'])) return $_SERVER['HTTP_X_FORWARDED']; elseif(!empty($_SERVER['HTTP_FORWARDED_FOR'])) return $_SERVER['HTTP_FORWARDED_FOR']; elseif(!empty($_SERVER['HTTP_FORWARDED'])) return $_SERVER['HTTP_FORWARDED']; elseif(!empty($_SERVER['REMOTE_ADDR'])) return $_SERVER['REMOTE_ADDR']; else return false; } if ($last_access = $mysqlcon->query("SELECT * FROM `$dbname`.`cfg_params` WHERE `param` IN ('webinterface_access_last','webinterface_access_count')")->fetchAll(PDO::FETCH_KEY_PAIR) === false) { $err_msg .= print_r($mysqlcon->errorInfo(), true); } require_once('nav.php'); $csrf_token = bin2hex(openssl_random_pseudo_bytes(32)); if ($mysqlcon->exec("INSERT INTO `$dbname`.`csrf_token` (`token`,`timestamp`,`sessionid`) VALUES ('$csrf_token','".time()."','".session_id()."')") === false) { $err_msg = print_r($mysqlcon->errorInfo(), true); $err_lvl = 3; } if (($db_csrf = $mysqlcon->query("SELECT * FROM `$dbname`.`csrf_token` WHERE `sessionid`='".session_id()."'")->fetchALL(PDO::FETCH_UNIQUE|PDO::FETCH_ASSOC)) === false) { $err_msg = print_r($mysqlcon->errorInfo(), true); $err_lvl = 3; } if (($last_access['webinterface_access_last'] + 1) >= time()) { $again = $last_access['webinterface_access_last'] + 2 - time(); $err_msg = sprintf($lang['errlogin2'],$again); $err_lvl = 3; } elseif (isset($_POST['resetpw']) && isset($db_csrf[$_POST['csrf_token']]) && ($cfg['webinterface_admin_client_unique_id_list']==NULL || count($cfg['webinterface_admin_client_unique_id_list']) == 0)) { $err_msg = $lang['wirtpw1']; $err_lvl=3; } elseif (isset($_POST['resetpw']) && isset($db_csrf[$_POST['csrf_token']])) { $nowtime = time(); $newcount = $last_access['webinterface_access_count'] + 1; if($mysqlcon->exec("INSERT INTO `$dbname`.`cfg_params` (`param`,`value`) VALUES ('webinterface_access_last','{$nowtime}'),('webinterface_access_count','{$newcount}') ON DUPLICATE KEY UPDATE `value`=VALUES(`value`)") === false) { } require_once(substr(__DIR__,0,-12).'libs/ts3_lib/TeamSpeak3.php'); try { if($cfg['teamspeak_query_encrypt_switch'] == 1) { $ts3 = TeamSpeak3::factory("serverquery://".rawurlencode($cfg['teamspeak_query_user']).":".rawurlencode($cfg['teamspeak_query_pass'])."@".$cfg['teamspeak_host_address'].":".$cfg['teamspeak_query_port']."/?server_port=".$cfg['teamspeak_voice_port']."&ssh=1"); } else { $ts3 = TeamSpeak3::factory("serverquery://".rawurlencode($cfg['teamspeak_query_user']).":".rawurlencode($cfg['teamspeak_query_pass'])."@".$cfg['teamspeak_host_address'].":".$cfg['teamspeak_query_port']."/?server_port=".$cfg['teamspeak_voice_port']."&blocking=0"); } try { usleep($cfg['teamspeak_query_command_delay']); $ts3->selfUpdate(array('client_nickname' => "Ranksystem - Reset Password")); } catch (Exception $e) { } try { usleep($cfg['teamspeak_query_command_delay']); $allclients = $ts3->clientList(); $pwd = substr(str_shuffle('abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789#*+;:-_~?=%&!()'),0,12); $cfg['webinterface_pass'] = password_hash($pwd, PASSWORD_DEFAULT); foreach($allclients as $client) { if(array_key_exists(htmlspecialchars($client['client_unique_identifier'], ENT_QUOTES), $cfg['webinterface_admin_client_unique_id_list'])) { $checkuuid = 1; if($client['connection_client_ip'] == getclientip()) { $checkip = 1; if($mysqlcon->exec("INSERT INTO `$dbname`.`cfg_params` (`param`,`value`) VALUES ('webinterface_pass','{$cfg['webinterface_pass']}'),('webinterface_access_last','0') ON DUPLICATE KEY UPDATE `value`=VALUES(`value`)") === false) { $err_msg .= $lang['isntwidbmsg'].print_r($mysqlcon->errorInfo(), true); $err_lvl = 3; } else { try { usleep($cfg['teamspeak_query_command_delay']); $ts3->clientGetByUid($client['client_unique_identifier'])->message(sprintf($lang['wirtpw4'], $cfg['webinterface_user'], $pwd, '[URL=http'.(!empty($_SERVER['HTTPS'])?"s":"").'://'.$_SERVER['SERVER_NAME'].dirname($_SERVER['SCRIPT_NAME']).']','[/URL]')); $err_msg .= sprintf($lang['wirtpw5'],'',''); $err_lvl = 1; enter_logfile($cfg,3,sprintf($lang['wirtpw6'],getclientip())); } catch (Exception $e) { $err_msg .= $lang['errorts3'].$e->getCode().': '.$e->getMessage(); $err_lvl = 3; } } } } } if (!isset($checkuuid)) { $err_msg = $lang['wirtpw2']; $err_lvl = 3; } elseif (!isset($checkip)) { $err_msg = $lang['wirtpw3']; $err_lvl = 3; } } catch (Exception $e) { $err_msg = $lang['errorts3'].$e->getCode().': '.$e->getMessage(); $err_lvl = 3; } } catch (Exception $e) { $err_msg = $lang['errorts3'].$e->getCode().': '.$e->getMessage(); $err_lvl = 3; } } elseif(isset($_POST['resetpw'])) { echo '
',$lang['errcsrf'],'
'; rem_session_ts3($rspathhex); exit; } ?>